budge

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
references/INSTALL.md

This fragment integrates a third-party CDN-hosted self-executing script (https://www.budge.design/budge.iife.js) into multiple frameworks with no SRI/integrity pinning shown, creating a supply-chain execution risk. It also describes MutationObserver-based activation using DOM/class/style changes and optional JSON config via a hidden data-budge element, increasing runtime behavioral opacity. No direct evidence of credential theft/exfiltration is present in the shown code, but the actual IIFE content is not provided, so malicious behavior cannot be fully assessed.

Confidence: 63%Severity: 55%
Audit Metadata
Analyzed At
May 14, 2026, 02:26 PM
Package URL
pkg:socket/skills-sh/ben-million%2Fskills%2Fbudge%2F@9b35500d457792c591e2d775ed1a79bbf52d9542